Threat Intelligence

Fake IT Help Desk Calls Used to Steal Microsoft 365 Logins and Extort Executives

The Hacker News · 8 Sept 2026
Key Takeaway Train executives and staff to independently verify any unexpected IT support call before entering credentials or approving MFA prompts, ideally by calling back through a known internal number.

Security researchers at Arctic Wolf have detailed an active threat campaign targeting directors, vice presidents and other senior staff through fake IT help desk phone calls. Victims are directed to convincing but fake login pages that mimic their organisation's Microsoft 365 sign-in process, designed to capture both passwords and multi-factor authentication approvals in real time.

Once attackers capture a valid session token, they can bypass MFA entirely and log in as the victim from proxy servers positioned to look like they are coming from the same city and internet provider as the target, making the activity harder to spot. From there, attackers explore SharePoint files and the organisation's identity systems (Entra ID) to locate sensitive data before using it for extortion. Researchers say this activity overlaps with other known extortion groups, suggesting a shared pool of phishing infrastructure and tactics rather than a single identifiable gang.

The campaign highlights how attackers are moving beyond simple phishing emails toward more convincing, human-driven social engineering that specifically targets senior decision-makers with access to sensitive systems.

Microsoft 365 vishing phishing MFA bypass data extortion

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.